release: website on Astro 7 and security updates - #87
Merged
Merged
Conversation
The website installed @chatcops/core and @chatcops/server 0.2.0 from npm. When a release moved them out of that range, changesets rewrote the ranges and pnpm install --frozen-lockfile failed in the release run. Use workspace:^ like the widget already does, so the site always runs the code in this repo and releases don't touch its ranges.
* chore(deps-dev): bump vitest from 3.2.4 to 4.1.11 Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 3.2.4 to 4.1.11. - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.1.11/packages/vitest) --- updated-dependencies: - dependency-name: vitest dependency-version: 4.1.11 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com> * chore(deps): bump website sharp to 0.35.4 Security fix from #81, on top of the vitest 4.1.11 upgrade from #80. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…flare 14 (#85) Fixes the open Astro security alerts on the docs site, including the critical image optimization RCE (fixed in 7.2.8). - wrangler main points at @astrojs/cloudflare/entrypoints/server - imageService 'compile' keeps build-time image handling (the v14 default would switch to the Cloudflare Images binding) - prerenderEnvironment 'node' and wasm32 installs for Starlight's Markdown pipeline (satteri), which resolves to its wasm build in the Worker bundle - compressHTML stays true, session: false (no SESSION KV namespace) - wrangler ^4.146 for the new adapter
…kages (#86) - happy-dom 16 to 20.14.5 and vite to 6.4.3 in the widget (dev only) - refresh body-parser, form-data, js-yaml, nanoid, path-to-regexp, picomatch, postcss, postcss-selector-parser, qs and yaml to their patched versions within the same major (lockfile only)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ships what's on
devsince the 0.4.0 / 0.3.0 release. No package changes and no changesets, so nothing is published to npm. Only the website redeploys.The deploy now uses
@astrojs/cloudflare/entrypoints/serveras the Workermain. The build writeswebsite/dist/server/wrangler.json, andwrangler deploypicks it up throughwebsite/.wrangler/deploy/config.json.